All about SPDX 3.0

SPDX is one of the three SBOM specifications recommended by NTIA/CISA.

The SPDX team is working on a significant update — SPDX version 3.0, targeted for general availability this fall. SPDX 3.0 packs features that cover new SBOM use cases and simplify existing capabilities.

Let's' dig in.

SPDX Profiles

Snipped from https://raw.githubusercontent.com/spdx/spdx-3-model/main/model.png

SPDX's' flexibility is contained in a new abstraction called ''Profile''. SPDX Profiles describes a specific use case for the SPDX document. Therefore, a document applicable to a specific use case can leave the details for another Profile.

To achieve this, SPDX fields from version 2.3 (with some changes) are segmented into three groups

Click Here

Tags: Software SPDX